US9438416B2

Customizable encryption algorithm based on a sponge construction with authenticated and non-authenticated modes of operation

Summary by NHIP

Sponge Construction Encryption

The method generates encrypted data by combining a key with initialization bits to create a keystream via a four-layer permutation function. This function iterates R times through substitution, permutation, mixing of at least two outputs, and adding a constant to the mixing layer output.

Claim Score by NHIP

Read claim 11, the broadest

Abstract

Systems (100) and methods (600) for generating encrypted data. The methods involve: combining a cryptographic key with state initialization bits to generate first combination bits; producing a first keystream by performing a permutation function ƒ using the first combination bits as inputs thereto; and using the first keystream to encrypt first data (e.g., authentication data or message body data) so as to produce first encrypted data. The permutation function ƒ comprises a round function ƒround that is iterated R times. The round function ƒround consists of (1) a substitution layer in which the first combination bits are substituted with substitute bits, (2) a permutation layer in which the substitute bits are re-arranged, (3) a mixing layer in which multiple of the permutation layer are combined together, and (4) an addition layer in which a constant is added to the output of the mixing layer.

US9438416B2, drawing sheet 1
Sheet 1 of 20

Term

8 yearsleft in the term

Expires 19 September 2034, including 63 days of term adjustment.

  1. Priority and filed
  2. Granted
  3. Today
  4. Expires

20 claims: 4 independent, 16 dependent

  1. 1
    A method for generating encrypted data, comprising:combining, by an electronic circuit, a cryptographic key with state initialization bits to generate first combination bits, the state initialization bits comprising bits b that have been initialized to pre-defined bit values;producing a first keystream by performing a permutation function ƒ using the first combination bits as inputs thereto, the permutation function ƒ comprising a round function ƒ round that is iterated R times, the round function ƒ round consisting of (1) a substitution layer in which the first combination bits are substituted with substitute bits, (2) a permutation layer in which the substitute bits are re-arranged, (3) a mixing layer in which at least two outputs of the permutation layer are combined together, and (4) an addition layer in which a constant is added to the output of the mixing layer;and using, by the electronic circuit, the first keystream to encrypt first data so as to produce first encrypted data.
  2. 9
    A method for generating encrypted data, comprising:combining, by an electronic circuit, a cryptographic key with state initialization bits to generate first combination bits;producing a first keystream by performing a permutation function ƒ using the first combination bits as inputs thereto, the permutation function ƒ comprising a round function ƒ round that is iterated R times, the round function ƒ round consisting of (1) a substitution layer in which the first combination bits are substituted with substitute bits, (2) a permutation layer in which the substitute bits are re-arranged, (3) a mixing layer in which at least two outputs of the permutation layer are combined together, and (4) an addition layer in which a constant is added to the output of the mixing laver;and using, by the electronic circuit, the first keystream to encrypt first data so as to produce first encrypted data;wherein the first encrypted data is produced by: combining the first keystream with authentication data to generate second combination bits;producing a second keystream by performing the permutation function ƒ using the second combination bits as inputs thereto;and combining the second keystream with message body data so as to produce the first encrypted data.
  3. 11
    Broadest claimClaim Score 51, average(NHIP)A system, comprising:an electronic circuit combining a cryptographic key with state initialization bits to generate first combination bits, the state initialization bits comprising bits b that have been initialized to pre-defined bit values, producing a first keystream by performing a permutation function ƒ using the first combination bits as inputs thereto, and using the first keystream to encrypt first data so as to produce first encrypted data;wherein the permutation function ƒ comprises a round function ƒ round that is iterated R times, the round function ƒ round consisting of (1) a substitution layer in which the first combination bits are substituted with substitute bits, (2) a permutation layer in which the substitute bits are re-arranged, (3) a mixing layer in which at least two outputs of the permutation layer are combined together, and (4) an addition layer in which a constant is added to the output of the mixing layer.
  4. 19
    A system, comprising:an electronic circuit combining a cryptographic key with state initialization bits to generate first combination bits, producing a first keystream by performing a permutation function ƒ using the first combination bits as inputs thereto, and using the first keystream to encrypt first data so as to produce first encrypted data;wherein the permutation function ƒ comprises a round function ƒ round that is iterated R times, the round function ƒ round consisting of (1) a substitution layer in which the first combination bits are substituted with substitute bits, (2) a permutation layer in which the substitute bits are re-arranged, (3) a mixing layer in which at least two outputs of the permutation layer are combined together, and (4) an addition layer in which a constant is added to the output of the mixing layer;and wherein the first encrypted data is produced by: combining the first keystream with authentication data to generate second combination bits;producing a second keystream by performing the permutation function ƒ using the second combination bits as inputs thereto;and combining the second keystream with message body data so as to produce the first encrypted data.